INFOGRAPHIC

Who Can Actually Access Your Network?

Senior technology leaders must understand every entity that can traverse the corporate network and the controls that govern that access. This matrix clarifies actor categories, access pathways, and the identity‑centric safeguards required to enforce least‑privilege at scale.

Template: EXECUTIVE_MATRIXPublished: 9/14/2026
THE ARCHON

Who Can Actually Access Your Network?

Mapping actors, vectors, and controls for Zero‑Trust Network Access

Senior technology leaders must understand every entity that can traverse the corporate network and the controls that govern that access. This matrix clarifies actor categories, access pathways, and the identity‑centric safeguards required to enforce least‑privilege at scale.

Actor Landscape
Key entities that request network connectivity, grouped by relationship and risk profile.
  • Employees (full‑time staff)
  • Contractors & temporary workers
  • Business partners & suppliers
  • Managed service accounts (automation, CI/CD)
  • IoT/OT devices
  • Guest devices (BYOD, visitor Wi‑Fi)
  • External threat actors (post‑compromise)
Access Vectors
Primary pathways through which actors attempt to reach network resources.
  • Corporate LAN/Wi‑Fi
  • Remote VPN / ZTNA gateways
  • SASE edge nodes
  • Direct cloud‑to‑cloud interconnects
  • Device‑to‑device (mesh) links
  • Third‑party SaaS APIs
Control Matrix (Identity‑Centric Zero Trust)
Mapping of essential controls that must be applied for each actor‑vector intersection.
  • Strong MFA (password‑less where possible)
  • Risk‑based adaptive authentication
  • Just‑In‑Time (JIT) privileged access
  • Device posture assessment (MDM/EDR compliance)
  • Micro‑segmentation / policy‑based network zones
  • Continuous session monitoring & analytics
  • Zero‑Trust Network Access (ZTNA) enforcement
Governance & Accountability
Executive‑level oversight mechanisms to ensure the matrix stays current and enforced.
  • Define clear ownership: IAM team for identity, Network Security team for segmentation
  • Quarterly access‑rights review aligned to business role changes
  • Automated entitlement revocation for inactive or orphaned accounts
  • Metrics: % of connections with ZTNA, MFA adoption rate, segmentation breach attempts

Technology Radar Domains

NetworkingIdentity